Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Scans show trojan that can't be removed


  • This topic is locked This topic is locked

#46
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Ok this one is persistent. Lets try a system restore.

Open task manager > File Menu > New Task Run then type in the following:

%systemroot%\system32\restore\rstrui.exe

It will open the system restore dialog box. Choose the third to the last restore point from today.

Tell me how it goes.
  • 0

Advertisements


#47
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Ok, is that third to the last restore point still from today or do you mean it has to be from 3 days ago?
  • 0

#48
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
The third from the last.
  • 0

#49
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Ok, I'll log out...
  • 0

#50
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hi from the healthy one,

When I type that in the New Task Run box, a message with a big red cross pops up saying
"Windows could not find the file "C:\Windows\system32\restore\rstrui.exe"
Make sure it is spelled correctly and try again.
  • 0

#51
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
:D

Try this one:

%systemroot%\system32\rstrui.exe
  • 0

#52
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Yes that worked.

But there are only 2 restore points:

03/03/2011 2:49 a.m. Install: OTL Restore Point
02/03/2011 10:12 p.m. Install: ComboFix created restore point

I am 14 hours behind you.
Is is it normal that there are only two and do I restore to the Combofix one?
  • 0

#53
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Yes, we use the combofix restore point. :D Back to the past. What time is it there?
  • 0

#54
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
3:52 a.m. But I´m still fresh as a lettuce! :D

By the way, computer is restoring now.
  • 0

#55
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
"Windows can't start"
Should I go with the recommended Startup Repair?
  • 0

Advertisements


#56
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
Ok. :D
  • 0

#57
Salagubang

Salagubang

    Trusted Helper

  • Malware Removal
  • 3,891 posts
++++++++++++++++++++++++++++++++

On another note, I like you to create a temporary bootable CD which you can use as an alternative (if you need internet) when the good computer is away.

Download ISO image: xpud-0.9.2.iso (64MB)
Burn it using a CD-R or CD-RW drive.

You can use this CD to boot the computer to an XPUD environment. It has its own Firefox and totally immune to the viruses on your machine. It might come handy. :D

Note : If you do not know how to set your computer to boot from CD follow the steps here

+++++++++++++++++++++++++++++++++
  • 0

#58
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hey, it finished with Startup Repair and restarted, the accounts were displayed but when I logged in the ordinal 874 returned.
  • 0

#59
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts

++++++++++++++++++++++++++++++++

On another note, I like you to create a temporary bootable CD which you can use as an alternative (if you need internet) when the good computer is away.

Download ISO image: xpud-0.9.2.iso (64MB)
Burn it using a CD-R or CD-RW drive.

You can use this CD to boot the computer to an XPUD environment. It has its own Firefox and totally immune to the viruses on your machine. It might come handy. :D

Note : If you do not know how to set your computer to boot from CD follow the steps here

+++++++++++++++++++++++++++++++++


That sounds useful, thanks man.
  • 0

#60
thedeadlystoat

thedeadlystoat

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
So, do you want to take a break?
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP